Upsonic has vulnerability in Pickle Handler component that can lead to deserialization
Low severity
GitHub Reviewed
Published
Jun 19, 2025
to the GitHub Advisory Database
•
Updated Jul 9, 2025
Description
Published by the National Vulnerability Database
Jun 19, 2025
Published to the GitHub Advisory Database
Jun 19, 2025
Reviewed
Jul 9, 2025
Last updated
Jul 9, 2025
A vulnerability, which was classified as critical, has been found in Upsonic up to 0.55.6. This issue affects the function cloudpickle.loads of the file /tools/add_tool of the component Pickle Handler. The manipulation leads to deserialization. The exploit has been disclosed to the public and may be used.
References